CVE-2026-4404: Use of hard coded credentials in GoHarbor Harbor
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GoHarbor Harborto a version that resolves this vulnerability.Fixed in 2.15.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4404?
CVE-2026-4404 has a high severity rating due to the use of hard coded credentials allowing unauthorized access.
How do I fix CVE-2026-4404?
To mitigate CVE-2026-4404, users must change the default credentials in the configuration file after installation.
Which versions of GoHarbor are affected by CVE-2026-4404?
CVE-2026-4404 affects GoHarbor Harbor version 2.15.0 and below.
What risks does CVE-2026-4404 pose to users?
CVE-2026-4404 poses risks of unauthorized access, potentially compromising sensitive data and system integrity.
Are there any workarounds for CVE-2026-4404?
The primary workaround for CVE-2026-4404 is to ensure that default credentials are changed immediately after deployment.